Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill advertises use of an external API token and a Node script that generates images via the Neta service, which implies outbound network access, but the manifest does not declare that capability. Undeclared network behavior reduces transparency and can bypass user expectations or policy review, especially in an agent ecosystem where permissions are meant to signal sensitive actions.
